Data auditing method and system supporting secure deduplication based on block chain oracle machine
Through the combination of blockchain oracle and smart contracts, the problems of high TPA dependence and high data redundancy in cloud storage are solved, and safe and efficient data deduplication and auditing are achieved, reducing storage costs and improving data security and auditing efficiency.
Patent Information
- Application Number
- CN202510461623.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-14
- Publication Date
- 2025-08-01
AI Technical Summary
The existing cloud storage data auditing solutions have problems such as high TPA dependence, single point failure risk, insufficient performance and high data redundancy, resulting in increased storage costs and insufficient data security.
The blockchain oracle generates audit challenges, combined with blockchain smart contracts and improved random convergence encryption technology, realizes data encryption, deduplication and audit, and conducts regular challenges and audits to cloud service providers through oracle to ensure data security and verifiability of the deduplication process.
Effectively reduce the burden on data owners, improve storage utilization, ensure data security and credibility of deduplication process, reduce storage costs, realize batch audit and data recovery functions, and have stronger fault tolerance and adaptability.
Smart Images

Figure CN120407678A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information security, and particularly relates to a data audit method and system for supporting secure deduplication based on a blockchain oracle. Background Art
[0002] In the information age, with the increasing scale of data, in order to pursue data security and data usage convenience, a large amount of data is encrypted and stored in the cloud environment provided by cloud service providers (CSPs). Although cloud storage brings great convenience to data owners (DOs) in data management and maintenance, the data stored in CSPs is not under the direct control of DOs and may be affected by various internal and external security attacks. When there are conflicts of interest between CSPs and owners, how to define the security responsibilities between CSPs and DOs becomes a key issue urgently to be solved in cloud security applications. The research on audit schemes for encrypted cloud storage data is proposed under this background.
[0003] Currently, the audit of cloud data often adopts an audit scheme based on TPA, which usually includes three roles: DO, CSP, and TPA. TPA is a third-party auditor used to conduct a security audit on the data of DOs stored in CSPs. It adopts a "challenge - proof - verification" mechanism. DO sends a challenge to CSP, CSP generates a proof in response to the challenge based on the stored data and sends it to TPA, and TPA verifies the challenge and the proof and conducts an audit of the stored data. However, the data audit scheme based on TPA still has deficiencies in terms of adaptability, performance, etc. when facing large-scale stored data. First, data audit requires DOs to generate audit challenges, which means that as the amount of data and audit requirements in cloud storage increase, the audit process will bring an increasing burden to DOs, which is extremely inconvenient for DOs; second, relying on TPA for data audit has a risk of single-point failure. If TPA fails or is malicious, the audit results will lose credibility; third, TPA has performance limitations. As a single entity with limited resources, TPA cannot simultaneously handle a large number of audit requirements from multiple DOs.
[0004] To address the deficiencies of the TPA-based data auditing scheme, some researchers have proposed introducing blockchain into the cloud data auditing scheme. The unique features of blockchain, such as decentralization, tamper resistance, and traceability, provide new ideas for cloud data storage auditing. Blockchain oracles are secure, trustworthy, and highly efficient. By having the blockchain oracle assume the responsibilities of the DO to generate audit challenges and cooperate with the blockchain to complete the audit process, it can effectively help the DO reduce the burden, correctly complete the tasks of data encryption, decryption, and storage, and ensure that the stored data content is not exposed. At the same time, as part of the blockchain architecture, the oracle can perform the above operations honestly and credibly, avoiding the risk of single-point failure and having great potential in data auditing. In addition, nearly 75% of the data stored in the CSP is redundant, and this proportion even reaches 90% in backup and archival storage systems. With the increasing demand for data storage, such a high degree of data redundancy undoubtedly results in a huge waste of resources. Data deduplication technology can significantly reduce storage costs by screening and deleting redundant copies of stored data, making it very suitable for optimizing the overhead of cloud storage. The currently commonly used method for encrypting data deduplication is convergent encryption (CE). The DO generates a convergent key by hashing the data and then uses the convergent key to encrypt the data to obtain the ciphertext. Encrypting the same data with the same convergent key can make the generated ciphertexts consistent. Based on this mechanism, duplicate data retrieval and deletion of encrypted data can be achieved. There is also the use of randomized convergent encryption (RCE), which is a message-locked encryption (MLE) method. It adopts an additional tag checking mechanism to ensure the integrity of user data and has stronger security than the CE scheme. However, the existing deduplication schemes still have the problem of being difficult to verify. First, if the CSP deliberately changes the judgment result of duplicate data to non-duplicate during data deduplication, making the DO think that storage is still required, it can earn additional storage fees without having to store the data again. Second, for the same file from different DOs, the CSP can claim to have stored all of them while only storing one copy, thus obtaining the fees for multiple storage, but this behavior will spread the risk of data corruption to all DOs. Summary of the Invention
[0005] Therefore, the present invention provides a data auditing method and system based on a blockchain oracle that supports secure deduplication, which solves the problems of difficult traceability and large storage overhead caused by the separation of cloud storage data storers and owners.
[0006] According to the design solution provided by the present invention, on the one hand, a data audit method supporting secure deduplication based on a blockchain oracle is provided, including:
[0007] For the data to be stored by the data owner, the blockchain smart contract is used to call the oracle. The oracle encrypts and deduplicates the data to be stored by the data owner, uploads the deduplicated encrypted data to the cloud service provider, and uploads the encryption parameters to the blockchain for storage. The encryption parameters at least include the data owner's identity ID, the encryption key, and the data duplicate check hash value;
[0008] The cloud service provider signs an intelligent contract for audit response incentive rewards and punishments with the oracle and pays the corresponding margin, and stores the uploaded encrypted data;
[0009] The oracle regularly sends data audit challenges to the cloud service provider to utilize the cloud service provider to make corresponding challenge responses to the data audit challenges, and the blockchain smart contract audits the stored data according to the challenge responses.
[0010] As the data audit method supporting secure deduplication based on the blockchain oracle of the present invention, further, the oracle encrypts the data to be stored by the data owner, including:
[0011] The oracle performs BCH encoding on the data to be stored by the data owner to obtain encoded data, and divides the encoded data into several message blocks;
[0012] The oracle uses a hash function to generate a corresponding encryption key for each message block, splices each message block with the data owner's identity ID, and encrypts the spliced data with the encryption key to generate an encrypted ciphertext.
[0013] As the data audit method supporting secure deduplication based on the blockchain oracle of the present invention, further, the oracle deduplicates the data to be stored by the data owner, including:
[0014] Use a hash function to generate a hash value for the encrypted ciphertext for duplicate check;
[0015] Randomly select an identifier for the data to be stored. For the encrypted ciphertext of each message block, generate an identification tag based on the identifier and using a hash algorithm, and use the identification tags of the encrypted ciphertexts of each message block to form a tag set of the data to be stored; and generate an audit identifier of the data to be stored based on the identifier and using a hash algorithm;
[0016] Send the hash value, encrypted ciphertext, data owner identity ID, and audit identifier to the blockchain, so that the blockchain checks whether the corresponding data owner has stored the same data based on the hash value and the data owner identity ID by executing the smart contract function for preset data duplication checking, and feeds back the check result to the oracle;
[0017] The oracle deduplicates the data to be stored according to the check result, and sends the deduplicated data to be stored to the cloud service provider for storage.
[0018] As the data audit method based on blockchain oracle for supporting secure deduplication in the present invention, further, the oracle periodically sends data audit challenges to the cloud service provider, including:
[0019] The oracle queries across chains and generates a random subset of block positions for the block set. Each element in the random subset of block positions is generated based on the current state of the blockchain, and the current state of the blockchain is represented by the block hash and index;
[0020] Bind the block hash to the element in the random subset of block positions, and use the hash function to generate a random number of fixed length for each element in the random subset of block positions;
[0021] Generate an audit challenge by using the element in the random subset of block positions and the random number for verifying the element, send the audit challenge to the cloud service provider, and feed back the audit challenge to the blockchain smart contract.
[0022] As the data audit method based on blockchain oracle for supporting secure deduplication in the present invention, further, use the cloud service provider to make a challenge response to the data audit challenge, including:
[0023] For the audit challenge, the cloud service provider obtains the bilinear mapping value by using the public parameters and generates a corresponding linear combination of sampled blocks. The linear combination of sampled blocks is obtained by weighted summing the challenged block data with the random number in the audit challenge;
[0024] Map the bilinear mapping value to the finite field and bind it to the linear combination of sampled blocks to obtain the linear parameter; use the random number in the audit challenge to construct the ciphertext label exponential weight and generate the aggregated label by aggregating the exponential weights, and obtain the audit identifier of the ciphertext to be audited according to the audit challenge;
[0025] Generate a challenge response corresponding to the audit challenge based on the audit identifier, linear parameter, aggregated label, and bilinear mapping value, and send it to the blockchain smart contract.
[0026] As the data audit method based on blockchain oracle for supporting secure deduplication in the present invention, further, the blockchain smart contract audits the stored data according to the challenge response, including:
[0027] The blockchain smart contract executes a preset algorithm to audit and verify the challenge response;
[0028] If the audit verification passes, the margin is returned to the cloud service provider, and it is determined whether the data needs to be stored in the cloud service provider continuously;
[0029] If the audit verification fails, the cloud service provider is punished by deducting the margin, and the deducted margin is used as compensation and sent to the data owner.
[0030] As the data audit method based on the blockchain oracle for supporting secure deduplication of the present invention, further, before the oracle encrypts the data to be stored by the data owner, the oracle performs BCH coding on the data to be stored by the data owner, so that there is a corresponding relationship between the codes of each codeword, so as to perform data integrity verification according to the inter-code relationship when the data owner accesses the data.
[0031] As the data audit method based on the blockchain oracle for supporting secure deduplication of the present invention, further, performing data integrity verification according to the inter-code relationship includes:
[0032] For the data access requirement of the data owner, the blockchain smart contract is used to call the oracle, and the oracle downloads the corresponding data ciphertext from the cloud service provider and uses a hash function to generate the hash value corresponding to the data ciphertext, and uses the hash value as the data integrity identifier;
[0033] Obtain the key corresponding to the data owner's identity ID and the data duplicate check hash value from the cross-chain, and use the key to decrypt the data ciphertext to obtain the plaintext data;
[0034] Compare the data integrity identifier with the data duplicate check hash value. If the two are equal, the data ciphertext integrity verification passes. If they are different, the data ciphertext integrity verification fails. The decrypted plaintext data is used as the recombined data, and the BCH code is used to correct the errors of the recombined data to obtain the error-corrected data. The error-corrected data is divided into several message blocks, and a hash function is used to generate the encryption key for each message block, and it is compared with the key obtained from the blockchain. If they are equal, the error correction is successful, and the error-corrected data is stored in the new cloud service provider again. If they are not equal, the error correction fails.
[0035] On the other hand, the present invention also provides a data audit system based on the blockchain oracle for supporting secure deduplication, including: an encryption module, a storage module, and an audit module, wherein,
[0036] An encryption module, which is used for the data to be stored by the data owner, utilizes a blockchain smart contract to call an oracle, encrypts and deduplicates the data to be stored by the data owner through the oracle, uploads the deduplicated encrypted data to a cloud service provider, and uploads the encryption parameters to the blockchain for storage. The encryption parameters at least include the data owner's identity ID, a key, and a data duplicate check hash value;
[0037] A storage module, which is used for the cloud service provider to sign an intelligent contract for audit response incentive rewards and punishments with the oracle and pay the corresponding margin, and stores the uploaded encrypted data;
[0038] An audit module, which is used for the oracle to regularly send data audit challenges to the cloud service provider, so as to utilize the cloud service provider to make corresponding challenge responses to the data audit challenges, and the blockchain smart contract audits the stored data according to the challenge responses.
[0039] Advantages of the present invention:
[0040] Based on the blockchain data storage mode, the present invention realizes secure deduplication data audit based on the blockchain oracle. Aiming at the dual requirements of privacy protection and batch audit in cloud storage data audit, the homomorphic tagging technology is used to realize the audit of non-encrypted data and encrypted data under privacy protection, and batch audit is realized through the aggregation verification technology, significantly improving the data audit ability of the solution; Aiming at the high-efficiency and secure deduplication requirements under cloud storage data encryption, the random convergence encryption technology is improved to realize identity-based data convergence encryption, realize the verification and comparison of encrypted data, so as to ensure the security of the deduplication process while effectively improving the storage utilization rate of the solution. Further theoretical analysis and experimental data show that the solution of this case only has functions such as batch audit, secure deduplication, and data recovery, and also has more advantages in execution efficiency and functionality, and has stronger fault tolerance and adaptability. Description of the drawings
[0041] Figure 1 Schematic diagram of the data audit process based on the blockchain oracle for secure deduplication in the embodiment;
[0042] Figure 2 Schematic diagram of the principle framework of the data audit algorithm for secure deduplication in the embodiment;
[0043] Figure 3 Schematic diagram of the operation process of the data audit algorithm for secure deduplication in the embodiment;
[0044] Figure 4 Schematic diagram of the comparison of the running time in the data storage stage in the embodiment;
[0045] Figure 5 Schematic diagram of the comparison of the running time in the data download stage in the embodiment. Detailed implementation manners
[0046] To make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below with reference to the accompanying drawings and technical solutions.
[0047] The data stored in the DO often has duplicates and redundancies, which will bring a certain storage overhead. Therefore, the idea of deleting duplicate data can be adopted, and the CSP responsible for storage performs data deduplication to reduce the storage space occupancy and also reduce the expenditure on storing data in the DO. In the data auditing scenario, data deduplication not only reduces the storage burden of the CSP, but also can effectively improve the data auditing efficiency and play an important role in the storage and auditing of large-scale data. Therefore, the research on data auditing and data deduplication always goes hand in hand. In view of the characteristics of large data scale, high redundancy and insufficient security in cloud storage, in order to better store and manage data, data deduplication and data auditing have been widely studied and concerned. However, the existing deduplication and auditing solutions have problems such as difficult verification in the deduplication process, insufficient security, and low execution efficiency. For this reason, in the embodiments of the present invention, see Figure 1 as shown, a data auditing method supporting secure deduplication based on a blockchain oracle is provided, including:
[0048] S101. For the data to be stored by the data owner, use the blockchain smart contract to call the oracle, encrypt and deduplicate the data to be stored by the data owner through the oracle, upload the deduplicated encrypted data to the cloud service provider, and upload the encryption parameters to the blockchain for storage. The encryption parameters at least include the data owner identity ID, the secret key, and the data duplicate check hash value.
[0049] In the embodiments of this case, the data owner DO is the provider of data and the demander of services. The DO will transmit the data to be stored to the blockchain smart contract and entrust the blockchain to assign the oracle to be responsible for data storage, deduplication, and auditing tasks. The oracle is an entity responsible for data processing and transmission. For the data to be stored, the oracle will generate a convergence key according to the data, then encrypt and hash the data, and finally store the encrypted data in the CSP. When the DO needs to use the data, the data will be transmitted from the CSP in ciphertext form and passed to the DO after being decrypted by the oracle. During data auditing, the oracle issues an audit challenge to the CSP, the CSP makes a challenge response, and the blockchain smart contract audits the data according to the response.
[0050] Among them, encrypting the data to be stored by the data owner through the oracle can be designed to include:
[0051] The oracle performs BCH coding on the data to be stored by the data owner to obtain coded data, and divides the coded data into several message blocks;
[0052] The oracle uses a hash function to generate a corresponding encryption key for each message block, concatenates each message block with the data owner's identity ID, and encrypts the concatenated data using the encryption key to generate an encrypted ciphertext.
[0053] For the encrypted ciphertext, the oracle deduplicates the data to be stored by the data owner, which may include:
[0054] Use a hash function to generate a hash value for the encrypted ciphertext for duplicate checking;
[0055] Randomly select an identifier for the data to be stored. For the encrypted ciphertext of each message block, generate an identification tag for it based on the identifier and using a hash algorithm, and use the identification tags of the encrypted ciphertexts of each message block to form a tag set of the data to be stored; and generate an audit identifier for the data to be stored based on the identifier and using a hash algorithm;
[0056] Send the hash value, encrypted ciphertext, data owner's identity ID, and audit identifier to the blockchain, so that the blockchain checks whether the corresponding data owner has stored the same data based on the hash value and the data owner's identity ID and by executing a smart contract function for preset data duplication checking, and feeds back the check result to the oracle;
[0057] The oracle deduplicates the data to be stored according to the check result, and sends the deduplicated data to be stored to the cloud service provider for storage.
[0058] As Figure 2 shown, for the data to be stored, the OVESD algorithm (①-②) is adopted. The oracle uses a hash function to generate a hash value of the target data as the convergence key, and then uses the convergence key to encrypt the data. Due to the inherent property of the hash algorithm, the same hash value will definitely be generated for the same data, so the same encryption key and ciphertext can always be generated for the same group of data. Then, the oracle will calculate the hash value of the ciphertext again and transmit the ciphertext and the hash value to the blockchain. The blockchain compares the ciphertext of the data already stored with the ciphertext of the newly uploaded data. If the same ciphertext is found, it means that the same data is stored in the CSP. Then the CSP will no longer store the new data to save storage space. When storing the data, the CSP will sign a smart contract with the blockchain.
[0059] S102. The cloud service provider signs a smart contract for audit response incentive rewards and punishments with the oracle, pays the corresponding margin, and stores the uploaded encrypted data.
[0060] A cloud service provider (CSP) is an entity responsible for storing data. Before storing encrypted data, the CSP compares the already stored encrypted data with the newly uploaded encrypted data and deduplicates the same data. Since the absolute reliability of the CSP cannot be guaranteed, the data stored in the CSP may be accurate, or it may be false or tampered with. Therefore, regular audits are required. After the smart contract obtains the audit result of the data through verification, rewards and punishments will be imposed on the CSP according to the audit result, so as to encourage the CSP to provide honest and reliable services. A smart contract is an entity that helps users with data storage and data auditing. For the data to be stored, the smart contract will commission an oracle to process and store it in the CSP, and require the oracle to regularly audit the already stored data. The CSP will hand over the challenge response to the smart contract, and rely on the smart contract to verify the correctness of the challenge response, thus completing the data audit process and imposing rewards and punishments on the CSP according to the audit result.
[0061] S103. The oracle regularly sends data audit challenges to the cloud service provider to utilize the cloud service provider to make corresponding challenge responses to the data audit challenges, and the blockchain smart contract audits the stored data according to the challenge responses.
[0062] Specifically, the oracle regularly sending data audit challenges to the cloud service provider can be designed to include:
[0063] The oracle queries across chains and generates a random subset of block positions for the block set. Each element in the random subset of block positions is generated based on the current state of the blockchain, and the current state of the blockchain is represented by the block hash and index;
[0064] Bind the block hash to the elements in the random subset of block positions, and use a hash function to generate a random number of a fixed length for each element in the random subset of block positions;
[0065] Generate an audit challenge using the elements in the random subset of block positions and the random number for verifying the element, send the audit challenge to the cloud service provider, and feedback the audit challenge to the blockchain smart contract.
[0066] As Figure 2 In the algorithm framework shown, for the traceability requirements of the stored data, the OPPEA algorithm (①-⑤) is used for data auditing, so as to effectively define the responsibilities of the DO and the CSP. The oracle generates an audit challenge and sends it to the CSP, and the CSP generates a challenge response according to the stored encrypted data and hands over the response to the smart contract for judgment.
[0067] Specifically, the cloud service provider making a challenge response to the data audit challenge can be designed to include:
[0068] In response to the audit challenge, the cloud service provider uses public parameters to obtain bilinear mapping values and generate a corresponding linear combination of sampled blocks, where the linear combination of sampled blocks is obtained by weighted summing the challenged block data with random numbers in the audit challenge;
[0069] Map the bilinear mapping value to a finite field and bind it to the linear combination of sampled blocks to obtain linear parameters; use the random numbers in the audit challenge to construct ciphertext label exponential weights and generate an aggregated label by aggregating the exponential weights, and obtain the audit identifier of the audited ciphertext according to the audit challenge;
[0070] Generate a challenge response corresponding to the audit challenge based on the audit identifier, linear parameters, aggregated label, and bilinear mapping value and send it to the blockchain smart contract.
[0071] Among them, the blockchain smart contract audits the stored data according to the challenge response, including:
[0072] The blockchain smart contract executes a preset algorithm to audit and verify the challenge response;
[0073] If the audit verification passes, the deposit is returned to the cloud service provider, and it is judged whether the data needs to be stored in the cloud service provider continuously;
[0074] If the audit verification fails, the cloud service provider is punished by deducting the deposit, and the deducted deposit is used as compensation and sent to the data owner.
[0075] The smart contract determines whether the CSP has correctly stored the data by verifying the challenge response, thus completing the data audit without the participation of the TPA. And it supports batch auditing of multiple data, allowing the smart contract to verify the labels of these data simultaneously.
[0076] To improve the enthusiasm and reliability of data auditing, in the embodiments of this case, before the oracle encrypts the data to be stored by the data owner, the oracle also performs BCH coding on the data to be stored by the data owner, so that there is a corresponding relationship between the codes of each codeword, so as to perform data integrity verification according to the inter-code relationship when the data owner accesses the data.
[0077] Specifically, the data integrity verification according to the inter-code relationship can be designed to include:
[0078] For the data access requirements of the data owner, use the blockchain smart contract to call the oracle, download the corresponding data ciphertext from the cloud service provider through the oracle and use the hash function to generate the hash value corresponding to the data ciphertext, and use this hash value as the data integrity identifier;
[0079] Obtain the key corresponding to the data owner identity ID and the data duplicate check hash value from the cross-chain in the zone, use the key to decrypt the data ciphertext to obtain the plaintext data;
[0080] Compare the data integrity identifier with the data duplicate check hash value. If the two are equal, the integrity verification of the data ciphertext passes. If they are different, the integrity verification of the data ciphertext fails. Take the decrypted plaintext data as the recombined data, use the BCH code to correct the errors in the recombined data to obtain the error-corrected data, divide the error-corrected data into several message blocks, and use a hash function to generate the encryption key for each message block, and compare it with the key obtained from the blockchain. If they are equal, the error correction is successful, and the error-corrected data is stored back in the new cloud service provider. If they are not equal, the error correction fails.
[0081] As Figure 2 In the algorithm framework shown, the incentive compensation mechanism (⑤) of DO and CSP and the data recovery mechanism (⑦) based on error-correcting codes. Among them, the incentive compensation mechanism is mainly implemented by relying on smart contracts. Before data auditing, CSP inputs a certain amount of deposit; if it is found after auditing that CSP has stored the blockchain data completely, the smart contract will return CSP's deposit to it and give an additional storage fee as a reward; if the data stored by CSP is damaged, the smart contract will withhold CSP's deposit and give it to DO to make up for the loss of data lost by DO. The main idea of implementing the data recovery mechanism based on error-correcting codes is: use error-correcting codes to detect and correct errors in the stored data. Before the data is encrypted, in order to make it have the ability to detect and correct errors, the oracle will first perform BCH coding on the data to be stored. By adding redundant code elements to the original codewords, the difference between the codewords can be enlarged, and the generated new codewords will have a certain redundancy, and there will also be corresponding relationships between the codes of each codeword; in this way, after the data is decrypted, the codewords can be detected and corrected according to the established inter-code relationships.
[0082] Considering that the threats faced mainly come from two aspects. First, in the face of the needs of data storage and use, CSP may delete those data with less access to save its storage cost. At the same time, lie that these data are still safely stored, so as to obtain additional storage fees from the blockchain. Second, CSP may provide false data to the oracle, such as data fabricated for profit that was not originally stored, or data damaged due to various hacker attacks and hardware failures, which will result in the obtained data being false. To address the possible threats and improve the adaptability of the solution, the algorithm framework aims to achieve the following five security goals:
[0083] Data confidentiality: It is required that the plaintext is not exposed during data storage and during the transmission process between CSP and the oracle.
[0084] Storage correctness: If the CSP wants to pass the audit of the smart contract, it must store the data to be stored correctly.
[0085] Batch audit: It is required that the smart contract can complete the audit of multiple stored data in one verification. If the CSP wants to generate correct challenge responses in batch audits, it must store all the data to be audited correctly.
[0086] Duplicate removal result verifiability: Ensure that the result of the duplicate judgment on the data during the duplicate removal process cannot be tampered with by the CSP, and it can be verified whether the CSP stores the same files from different DOs separately.
[0087] Data integrity: The data from the CSP may be damaged due to various network failures during transmission. If the oracle decrypts damaged or false data, it will not be able to obtain the correct plaintext. Therefore, it is necessary to verify whether the decrypted data is complete and take measures to recover the damaged data. It is required that the oracle can verify the integrity of the acquired data and has the ability to recover data with less damage.
[0088] Through Figure 2 The algorithm architecture shown can not only efficiently implement privacy-preserving data auditing and verifiable secure duplicate removal, but also undertake tasks such as data encryption, data transmission, and initiating audit challenges through the oracle, effectively reducing the burden on the DO brought by auditing and duplicate removal, and also significantly improving the execution efficiency of the scheme. The incentive compensation mechanism and data recovery mechanism also enhance the usability of this scheme.
[0089] In the specific algorithm design, in order to meet the efficient and secure auditing requirements of cloud storage data and ensure the privacy of data during the auditing process, the OPPEA algorithm is designed and provided. For the auditing requirements of the mixture of non-encrypted data and encrypted data, the algorithm uses homomorphic tagging technology to design a data auditing method that can audit non-encrypted data and encrypted data simultaneously. By requiring the CSP to respond to the generated tags, it can complete the data audit without downloading the data. For the problems of low auditing efficiency, dependence on the TPA, and insufficient security of the auditing process, the algorithm designs an oracle-based auditing mechanism that can efficiently implement data auditing without relying on an external TPA and obtain a fair auditing result relying on the smart contract. For the requirement of auditing a large amount of data simultaneously, the algorithm implements a batch auditing mechanism based on tag aggregation technology, allowing the simultaneous verification of the CSP's challenge responses to multiple data by aggregating tags. The algorithm also uses the oracle to replace the DO to complete data processing and audit challenges, effectively reducing the burden on the DO. The symbols used in the algorithm are shown in Table 1.
[0090] Table 1. Symbol description.
[0091]
[0092] The OPPEA algorithm consists of the following modules: System Initialization OPPEA.Setup, Tag Generation OPPEA.TagGen, Audit Challenge Generation OPPEA.ChalGen, Challenge Response Generation OPPEA.ResGen, and Audit Verification OPPEA.Verify. In addition, there are modules designed specifically for batch auditing: Batch Challenge Generation OPPEA.BatchChalGen, Batch Response Generation OPPEA.BatchResGen, and Batch Audit Verification OPPEA.BatchVerify.
[0093] OPPEA.Setup: Assume that G1, G2, and G T are three different multiplicative cyclic groups, and the order of the group is p. Let g represent the generator of G2, and e: G1 × G2 → G T be a bilinear mapping. H(·) is a secure hash function {0,1} * → G1. h(·) is a secure hash function f is a pseudorandom function: {0,1} * → n, where n is the number of ciphertexts. The oracle randomly selects a random number and computes v ← g x . Then randomly select an element u ← G1. The secret parameter is sk = x. The public parameter is pk = (v, u, g, e(u, v)).
[0094] OPPEA.TagGen: For the ciphertexts C = {C1, C2,..., C n} corresponding to the data F, the oracle generates tags where W i = name||i, and is randomly selected as the identifier of the data F and remains consistent throughout the processing of the data F. Φ = {σ i} 1≤i≤n represents the set of tags. The generated audit identifier (file auditing id) is t = name||H(name), where H(name) is the hash value of name.
[0095] OPPEA.ChalGen: After querying the blockchain, the oracle generates a random subset I = a1, a2,..., a c of [1, n] with c elements, where a i = f(blockhash||i). Then for each ai For each i ∈ I, a random number is generated The generated audit challenge The position of the challenge block is declared in. The oracle will send the audit challenge chal to the CSP. Since the challenge value is calculated using the latest hash value of the blockchain, malicious attackers cannot predict the next challenge value. Therefore, the man-in-the-middle attack and replay attack can be effectively resisted by the algorithm in this case.
[0096] OPPEA.ResGen: After the CSP receives the audit challenge chal, let R = e(u, v) ∈ G T Then generate a linear combination of sampled blocks And calculate μ = h(R)μ', where And generate an aggregated tag Then find the audit identifier t of the ciphertext to be audited according to chal, form the challenge response Res = {t, μ, σ, R} and send it to the smart contract. Because the random subset I and random numbers are used Therefore, the CSP must save all ciphertexts to ensure that μ can be correctly calculated.
[0097] OPPEA.Verify: After the smart contract receives the challenge response Res = {t, μ, σ, R}, execute Algorithm 1. The proof of the correctness of a = b is shown in Formula (1):
[0098]
[0099]
[0100] OPPEA.BatchChalGen: For multiple data F1, F2, …, F s whose ciphertexts are to be audited, the oracle generates a random subset I = a1, a2, …, ac of [1, n] with c elements c , where a i = f(blockhash||i). For each a i ∈ I, the oracle generates a random number The audit challenge chal randomly specifies the data blocks to be audited from multiple data to be audited. The oracle will send it to the CSP.
[0101] OPPEA.BatchResGen: After receiving the audit challenge chal, the CSP sets R = e(u, v) ∈ G T . For each C d (1 ≤ d ≤ s), the CSP generates a linear combination of sampled blocks And calculate μd = h(R)μ d ', where Then the CSP generates the aggregated tags Then, according to chal, the audit identifiers t1, t2, …, t of the audited ciphertexts are found s , forming the batch challenge responses {μ1, μ2, …, μ s , σ1, σ2, …, σ s , R} and sending them to the smart contract
[0102] OPPEA.BatchVerify: After receiving the challenge responses {t1, t2, …, t s , μ1, μ2, …, μ s , σ1, σ2, …, σ s , R}, the smart contract executes Algorithm 2. The proof of the correctness of a = b is shown in Equation (2) as follows
[0103]
[0104] Relying on the architecture of the blockchain oracle, the OPPEA algorithm realizes the batch auditing of data based on the oracle, which not only meets the privacy protection data auditing requirements of DO, but also completes the fair and just public auditing through the smart contract, ensuring the correctness of the audit results
[0105]
[0106] To solve the problem of verifiable deduplication of encrypted data in cloud storage, the OVESD algorithm is designed and provided. Aiming at the problem that it is difficult to distinguish the same data of different users, the algorithm improves the random convergent encryption technology by introducing identity identifiers, so that the improved random convergent encryption technology can distinguish the same data of different users. Aiming at the problems that it is difficult to verify the repetitive judgment results and it is difficult to guarantee the deduplication process, the algorithm designs the oracle-based data convergent encryption and data repetitive judgment, relying on the oracle to efficiently complete data encryption and data deduplication, ensuring the security in the data processing process
[0107] The OVESD algorithm includes the following modules: system initialization OVESD.Setup, key generation OVESD.KeyGen, data convergent encryption with identity identifiers introduced OVESD.Enc, duplicate identifier generation OVESD.DupTagGen, data deduplication for distinguishing DO identities OVESD.Dedup, and data decryption OVESD.Dec
[0108] OVESD.Setup: Assume G1, G2, and G TThey are three different multiplicative cyclic groups, and the order of the group is p. Let g represent the generator of G2, and e: G1×G2→G T is a bilinear mapping. H(·) is a secure hash function {0,1} * →G1.
[0109] OVESD.KeyGen: When storing the encoded data F, the oracle first divides the data F into a set of data blocks {M1, M2, …, M n}. For the block M i , the oracle uses the hash function H(·) to generate the hash value of the data M i as the encryption key K i ←H(M i ).
[0110] OVESD.Enc: The oracle concatenates the plaintext M i and the identity ID of DO, and then encrypts to generate the ciphertext C i ←Encrypt(K i , M i ||ID).
[0111] OVESD.DupTagGen: The oracle uses the secure hash function H(·) to generate the hash value T i of the ciphertext data C i ←H(C i ), and uploads {K i , T i , ID} to the blockchain.
[0112] OVESD.Dedup: The smart contract compares T i with the previously uploaded hash values of the ciphertexts of this ID {T i 1 , T i 2 , …, T i m}. If there are any identical ones, it means that C i has already been stored in the CSP, and then C i will not be stored again.
[0113] OVESD.Dec: The oracle obtains the uploaded key K i and the hash value T i of the ciphertext data from the blockchain, and uses the key K i to decrypt the ciphertext C i to obtain the plaintext M i .
[0114] Different from the existing solutions that rely on TPA or CSP for data deduplication, data deduplication in the OVESD algorithm is completed by the oracle and the smart contract, which not only avoids the dependence on TPA but also prevents CSP from tampering with the duplicate judgment results, achieving full control over the deduplication process. At the same time, since the identity ID of the DO is added during the data storage process, it can ensure that the ciphertexts of the same data of different DOs are different, allowing the data stored by each DO to be verified separately, avoiding CSP violations and reducing the data storage volume.
[0115] For the data that needs to be stored and audited, in the specific algorithm implementation of this case, the oracle, CSP, and smart contract are organized to process according to the following process: algorithm initialization, encoding, storage, auditing, downloading, error correction. If batch auditing is required, the auditing process is replaced by the batch auditing process. The operation processes in stages such as storage, auditing, and downloading in the solution are as Figure 3 shown, and the specific process of the algorithm can be summarized as follows:
[0116] Suppose G1, G2, and G T are three different multiplicative cyclic groups, and the order of the group is p. g represents the generator of G2, and e: G1×G2→G T is a bilinear mapping. H(·) is a secure hash function {0,1} * →G1. h(·) is a secure hash function f is a pseudorandom function: {0,1} * →n, where n is the number of ciphertexts.
[0117] ① Algorithm initialization: The oracle executes the OPPEA.Setup algorithm, randomly selects a random number and calculates v←g x . Then, the oracle randomly selects an element u←G1. The secret parameter is sk = x. The public parameter is pk = (v, u, g, e(u, v)).
[0118] ② Encoding: For the data D to be stored, the oracle first encodes D according to the BCH encoding method to obtain the encoded data F.
[0119] ③ Storage: When storing the encoded data F, the oracle first divides the data F into a group of message blocks {M1, M2,..., M n}}. For the message block M i , the following operations are performed:
[0120] Key generation: The oracle executes the OVESD.KeyGen algorithm to generate the encryption key K i ←OVESD.KeyGen(M i i )。
[0121] Data Encryption: The oracle takes the plaintext M i , the encryption key K i and the identity ID of DO as inputs, and executes the OVESD.Enc algorithm to generate the ciphertext C i ←OVESD.Enc(K i ,M i ,ID).
[0122] Duplicate Check Identifier Generation: The oracle executes the OVESD.DupTagGen algorithm to generate the duplicate check identifier T of Ci i ←OVESD.DupTagGen(C i ).
[0123] Audit Tag Generation: The oracle executes the OPPEA.TagGen algorithm to generate σ i ,Φ,t←OPPEA.TagGen(C i ,u,x). Where Φ = {σ i} 1≤i≤n represents the set of tags. Then, the oracle sends {t, Ki, ID, Ti} to the blockchain.
[0124] Data Duplication Check: After receiving Ti and ID, the blockchain requests the smart contract to execute the OVESD.Dedup algorithm for duplication check, checks whether the DO corresponding to ID has already stored the same data, and returns the check result to the oracle.
[0125] Data Deduplication and Storage: According to the duplication check result, the oracle executes the deduplication and storage tasks. If the data is determined to be non-duplicate, the oracle sends {C1, C2, …, C n ,Φ,t} to the CSP for storage, and requests the CSP to sign the smart contract and send deposit CSP to the smart contract as the CSP's margin. If the data is determined to be duplicate, the oracle will no longer store the data.
[0126] ④Audit: To ensure the validity of the data, the oracle needs to audit the data stored on the CSP regularly. The audit process is described as follows:
[0127] Audit Challenge Generation: The oracle executes the OPPEA.ChalGen algorithm to generate chal←OPPEA.ChalGen() and sends chal = {(a i ,n ai )} ai∈I to the CSP, and then sends {t, chal} to the smart contract.
[0128] Challenge response generation: After receiving the challenge chal, the CSP executes the OPPEA.ResGen algorithm, obtains μ, σ, R←OPPEA.ResGen(), and sends Res = {t, μ, σ, R} to the smart contract.
[0129] Audit result verification: After receiving the challenge response Res, the smart contract executes the OPPEA.Verify algorithm for verification and obtains the verification result t. After the audit of the data is completed, the smart contract will send a fee to the miner as an audit fee. If the audit of the stored data fails, the smart contract will forfeit the CSP's deposit. CSP The CSP is penalized by deducting the deposit, and the DO is compensated by giving the deposit to the CSP. If the audit of the stored data passes, the smart contract automatically returns the CSP's deposit and then determines whether the data should continue to be stored with the CSP. If so, the contract continues to cooperate with the CSP. This ensures that incentives and compensation are paid to both the CSP and the DO based on the audit results.
[0130] ⑤ Download: During the download phase of the solution, the oracle performs the following operations:
[0131] Data download: Download ciphertext C1, C2, ..., C from CSP n .
[0132] Integrity identification generation: the ciphertext C i Input into OVESD.DupTagGen algorithm to generate integrity tag T i '.
[0133] Integrity verification and decryption: Get the previously uploaded key K from the blockchain i and the repeated identifier T of the ciphertext data i Then execute the OVESD.Dec algorithm to get the plaintext M i ←OVESD.Dec(C i ,K i ). And use T i 'With T i Compare and verify the integrity of the ciphertext. If they are equal, the ciphertext integrity verification passes; if they are not equal, the ciphertext integrity verification fails and enters the error correction phase.
[0134] ⑥ Error correction: Decrypted {M1,M2,…,M n} Recompose the data F, and then use the BCH code in the data F to correct the data to obtain data D'. By executing the OVESD.KeyGen algorithm, the M in D' is obtained. i 'The encryption key K i ', and with the key K iCompare. If they are equal, it means the error correction is successful, and the oracle will store the data D’ back into the new CSP; if they are not equal, it means the error correction fails.
[0135] When conducting a batch audit of the stored data, mainly replace "④ Audit" in the above process with "④ Batch Audit".
[0136] ④ Batch Audit: When conducting a batch audit, perform the following operations:
[0137] Batch Audit Challenge Generation: For multiple data that need to be batch audited, the oracle executes the OPPEA.BatchChalGen algorithm to generate Batchchal←OPPEA.BatchChalGen() and send it to the CSP.
[0138] Batch Challenge Response Generation: After receiving the challenge Batchchal, the CSP executes the OPPEA.BatchResGen algorithm to obtain μ1, μ2,..., μ s , σ1, σ2,..., σ s , R←OPPEA.BatchResGen(), and send BatchRes = {t1, t2,…, t s , μ1, μ2,…, μ s , σ1, σ2,…, σ s , R} to the smart contract.
[0139] Batch Audit Result Verification: After receiving the challenge response BatchRes, the smart contract executes the OPPEA.BatchVerify algorithm for verification. After obtaining the audit result, the smart contract implements reward and punishment measures for the CSP according to the incentive compensation mechanism.
[0140] Furthermore, based on the above method, an embodiment of the present invention also provides a data audit system based on a blockchain oracle that supports secure deduplication, including: an encryption module, a storage module, and an audit module, where
[0141] The encryption module is used to, for the data to be stored by the data owner, call the oracle using the blockchain smart contract, encrypt and deduplicate the data to be stored by the data owner through the oracle, upload the deduplicated encrypted data to the cloud service provider, and upload the encryption parameters to the blockchain for storage. The encryption parameters at least include the data owner identity ID, the key, and the data duplicate check hash value;
[0142] The storage module is used for the cloud service provider to sign an intelligent contract for audit response incentive rewards and punishments with the oracle and pay the corresponding deposit, and store the uploaded encrypted data;
[0143] An auditing module is used for the oracle to regularly send data auditing challenges to the cloud service provider, so as to utilize the cloud service provider to make corresponding challenge responses to the data auditing challenges, and the blockchain smart contract audits the stored data according to the challenge responses.
[0144] To verify the effectiveness of the solution in this case, the following further explains with the combination of theoretical analysis and experimental data:
[0145] 1. Comparative analysis of solutions
[0146] By comparing with the existing PDP solution, VeriDedup solution, DedupDUM solution, the solution of Li et al., and SecDedup solution, the advantages of the solution in this case in terms of functionality and security are comprehensively measured from multiple aspects such as TPA dependence, data deduplication function, tag consistency verification, data recovery function, batch auditing function, and data privacy protection ability. The comparison results between the solutions are shown in Table 2.
[0147] Table 2. Comparison of solutions.
[0148]
[0149] The VeriDedup solution designs verifiable data deduplication and uses a flexible tag generation technology to achieve the integrity verification of encrypted data. SecDedup applies a homomorphic authenticator and designs a multi-functional data tag, which can support deduplication and dynamic data auditing. However, both of these two solutions rely on TPA and have a single point of failure risk. DedupDUM is a data deduplication solution with a user management mechanism and a data auditing function. It uses group encryption to achieve the functions of dynamic user authorization and revocation. However, it lacks the relevant functions of data recovery and batch auditing. The PDP solution and the solution of Li et al. achieve the auditing of stored data through homomorphic verification tags, but both lack the function of data deduplication.
[0150] Compared with the above several solutions, the solution in this case realizes data deduplication and batch auditing without relying on TPA. It can not only ensure the security of the data storage process through tag consistency verification, but also has an incentive compensation mechanism and a data recovery mechanism, making the solution have stronger fault tolerance. Compared with other existing solutions, it has more advantages in terms of functionality, security, and fault tolerance.
[0151] 2. Experimental analysis
[0152] The solution was simulated in a virtual machine. The test was conducted on a VMware Workstation Pro platform using the Ubuntu 20.04 operating system. The processor parameters were a 12th Gen Intel(R) Core(TM) i9-12900H 2.50GHz processor with four cores and 8GB of memory. The solution was deployed using the C++ language, and the SHA-256 algorithm was implemented as a hash function.
[0153] The algorithm was executed to test the efficiency of this solution. The experiment focused on two aspects: the solution's performance during data storage and the solution's performance during data download. The results were compared with those of the CE solution, the LR solution, and the DedupDUM solution.
[0154] In the data storage phase of this solution, the oracle needs to perform operations such as key generation, data encryption, duplicate check mark generation, audit label generation, data duplication check, data deduplication and storage in sequence to complete the tasks of data encryption, data deduplication and data storage, and generate duplicate check marks and audit labels in the process. This phase actually includes the entire process of processing the data that needs to be stored, which can effectively reflect the execution efficiency of the solution when processing data. The performance of this phase is compared with other existing solutions to measure the performance of this solution. The performance of the solution in the data storage phase is as follows: Figure 4 As shown in the figure, during the data storage phase, the execution efficiency of this solution is significantly higher than that of the LR solution, slightly higher than that of the DepdupDUM solution, and roughly on par with that of the CE solution. This is because this solution uses homomorphic tagging technology to implement data possession proof and, by entrusting blockchain oracles to process data, avoids direct user interaction with the CSP, thus resolving the issue of user identity theft and achieving higher execution efficiency during the storage phase. The LR solution, on the other hand, implements data possession proof by constructing a Merkle tree. This requires the additional calculation and storage of the Merkle tree's leaf node values during data storage, which imposes a significant computational burden and results in significantly lower execution efficiency during the storage phase than other solutions.
[0155] The DedupDUM scheme uses group keys to authenticate user identities, preventing malicious users from impersonating others and illegally accessing data. Therefore, it also generates group keys during the data storage phase, which imposes an additional computational burden and makes its storage efficiency slightly lower than that of the proposed scheme. Compared to the CE scheme, the proposed scheme not only addresses the difficulty of verifying data deduplication by improving the randomized convergent encryption method, but also offers comparable efficiency.
[0156] In the data download phase of the solution in this case, the oracle needs to perform operations such as data download, integrity identifier generation, integrity verification, and decryption to complete the integrity verification and data decryption of the stored data. The purpose of this phase is to meet the user's need to obtain data, covering the entire process of data download, verification, and decryption, and can effectively measure the ability of the solution to obtain and process data from the CSP. The performance of the solution in the data download phase is as Figure 5 shown. It can be found that in the data download phase, the execution efficiency of the solution in this case is significantly higher than that of the DedupDUM solution, and is basically the same as that of the LR solution and the CE solution. This is because the solution in this case relies on the blockchain oracle, and there are strict control and traceability mechanisms for data flow and behavior control, so it has great advantages in the control of data operation behavior. The DedupDUM solution is committed to controlling the user's data download behavior by implementing an access control mechanism, and needs to add additional user identity authentication operations in the data download phase, resulting in the DedupDUM solution taking longer to execute the download phase and being significantly inferior to other solutions in terms of execution efficiency.
[0157] 3. Theoretical analysis
[0158] During the description of the algorithm, the audit correctness and batch audit correctness have been analyzed. The process of inferring that a = b can show that only when the CSP provides the correct challenge response can the smart contract verify that the audit passes, ensuring the correctness of the audit and batch audit.
[0159] Then, assume that the basic tools used are secure, including homomorphic linear verifiers, one-way hash functions, and symmetric encryption schemes, etc. These assumptions ensure the security of the solution. In the data storage phase, the oracle will use an encryption algorithm to encrypt the data, and the key used is the calculated convergent key, and then transmit the ciphertext to the CSP. In the case of using secure basic tools, the privacy of the stored data can be guaranteed.
[0160] Next, analyze the storage correctness of the data. It is proved that when the CSP does not correctly store the complete data, the CSP cannot generate the correct challenge response.
[0161] Theorem 1 Assume that the computational Diffie-Hellman problem is difficult in the bilinear group and the digital signature scheme is unforgeable. Then, in the random oracle model, unless the adversary correctly generates the proof {t, μ, σ, R} using the challenge chal and the ciphertext C, the probability that the auditor accepts this proof is negligible.
[0162] Proof 1 In the random oracle model, assume there is an extractor μ'. When there is a valid signature σ and μ', the theorem follows the above scheme.
[0163] The extractor can control the random oracle h(·). Then, the extractor can make hash queries and let the CSP reply. Assume the extractor is an adversary. To respond to the extractor's challenge z = H(R), the CSP will output {σ, μ, R} that satisfies the following equation:
[0164]
[0165] Suppose the extractor can reverse the CSP from the protocol execution phase to a time point before the challenge h(R) is determined. Then the extractor can set h(R) to z*≠z, and the CSP will return {σ, μ*, R} like this:
[0166]
[0167] Considering By splitting (3) through (4), we get:
[0168]
[0169] Then we have
[0170]
[0171] Finally, through reasoning, it can be found that to generate a challenge response that can pass the audit verification, the extractor must correctly store all the data and generate it according to the corresponding data in chal that contains randomness. This ensures the correct storage of the data and guarantees that when the CSP does not correctly store all the data, it cannot generate a valid challenge response according to chal.
[0172] Through the above comparison, experimental data, and theoretical analysis, it shows that the solution in this case assigns the deduplication task to a trusted oracle, and then hands the deduplicated data to the cloud storage service provider for storage, ensuring the security of the data during the deduplication process. Using the oracle to assist the blockchain in data deduplication and undertaking most of the data deduplication tasks can not only relieve the burden of cloud users but also determine which data has been stored by accessing the data fingerprints on the blockchain, thus ensuring correct data deduplication. And by improving the convergent encryption algorithm, the oracle can distinguish the same data of different users, avoiding the risk of incorrect deduplication of the same data from different users during the deduplication process, which brings risks to the data security of users. Further proof shows that compared with the existing solutions, the solution in this case not only has functions such as batch auditing, secure deduplication, and data recovery, but also has more advantages in terms of execution efficiency and functionality, and also has stronger fault tolerance and adaptability.
[0173] Unless otherwise specifically stated, the relative steps, numerical expressions, and values of the components and steps set forth in these embodiments do not limit the scope of the present invention.
[0174] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other. For the system disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple, and reference can be made to the description in the method part for the relevant parts.
[0175] The units and method steps of each example described in connection with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art can use different methods to implement the described functions for each specific application, but such implementation is not considered to exceed the scope of the present invention.
[0176] Those of ordinary skill in the art can understand that all or part of the steps in the above methods can be completed by instructing relevant hardware through a program. The program can be stored in a computer-readable storage medium, such as a read-only memory, a magnetic disk, or an optical disc, etc. Optionally, all or part of the steps of the above embodiments can also be implemented using one or more integrated circuits. Correspondingly, each module / unit in the above embodiments can be implemented in the form of hardware or in the form of a software functional module. The present invention is not limited to any specific form of the combination of hardware and software.
[0177] Finally, it should be noted that the above-described embodiments are only specific embodiments of the present invention, used to illustrate the technical solutions of the present invention, rather than to limit them. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed by the present invention can still modify or easily conceive of changes to the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications, changes, or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A data auditing method based on a blockchain oracle that supports secure deduplication, characterized in that Including: For the data to be stored by the data owner, the blockchain smart contract is used to call the oracle. The oracle encrypts and deduplicates the data to be stored by the data owner, uploads the deduplicated encrypted data to the cloud service provider, and uploads the encryption parameters to the blockchain for storage. The encryption parameters at least include the data owner identity ID, the secret key, and the data duplicate check hash value; The cloud service provider signs an intelligent contract for audit response incentive rewards and punishments with the oracle and pays the corresponding deposit, and stores the uploaded encrypted data; The oracle regularly sends data audit challenges to the cloud service provider to utilize the cloud service provider to make corresponding challenge responses to the data audit challenges, and the blockchain smart contract audits the stored data according to the challenge responses.
2. The data auditing method based on a blockchain oracle for supporting secure deduplication according to claim 1, characterized in that, Encrypting the data to be stored by the data owner through the oracle, including: The oracle performs BCH encoding on the data to be stored by the data owner to obtain encoded data, and divides the encoded data into several message blocks; The oracle uses a hash function to generate a corresponding encryption key for each message block, splices each message block with the data owner identity ID, and encrypts the spliced data using the encryption key to generate encrypted ciphertext.
3. The data auditing method based on blockchain oracle for supporting secure deduplication according to claim 2, wherein Deduplicating the data to be stored by the data owner through the oracle, including: Using a hash function to generate a hash value for duplicate check for the encrypted ciphertext; Randomly selecting an identifier for the data to be stored. For the encrypted ciphertext of each message block, based on the identifier and using a hash algorithm to generate an identification tag for it, and using the identification tags of the encrypted ciphertext of each message block to form a tag set of the data to be stored; and based on the identifier and using a hash algorithm to generate an audit identifier for the data to be stored; Sending the hash value, the encrypted ciphertext, the data owner identity ID, and the audit identifier to the blockchain, so that the blockchain checks whether the corresponding data owner has stored the same data based on the hash value and the data owner identity ID and by executing the intelligent contract function for preset data repeatability check, and feeds back the check result to the oracle; The oracle deduplicates the data to be stored according to the check result, and sends the deduplicated data to be stored to the cloud service provider for storage.
4. The data auditing method based on a blockchain oracle for supporting secure deduplication according to claim 1, characterized in that, The oracle regularly sends data audit challenges to the cloud service provider, including: The oracle queries cross-chain for the block set and generates a random subset of block positions for the block set. Each element in the random subset of block positions is generated according to the current state of the blockchain, and the current state of the blockchain is represented by the block hash and the index; Binding the block hash to the elements in the random subset of block positions, and using a hash function to generate a random number with a fixed length for each element in the random subset of block positions; Generating an audit challenge using the elements in the random subset of block positions and the random number for verifying the element, sending the audit challenge to the cloud service provider, and feeding back the audit challenge to the blockchain smart contract.
5. The data auditing method based on a blockchain oracle for supporting secure deduplication according to claim 1 or 4, characterized in that, Utilizing the cloud service provider to make a challenge response to the data audit challenge, including: For the audit challenge, the cloud service provider obtains a bilinear mapping value using public parameters and generates a corresponding sampled block linear combination. The sampled block linear combination is obtained by weighted summing the challenged block data with the random number in the audit challenge; Map the bilinear mapping value to a finite field and bind it to the linear combination of sampling blocks to obtain linear parameters; construct the ciphertext label exponential weights using the random numbers in the audit challenge and generate an aggregated label by aggregating the exponential weights, and obtain the audit identifier of the audited ciphertext according to the audit challenge. Generate a challenge response corresponding to the audit challenge based on the audit identifier, linear parameters, aggregated label, and bilinear mapping value and send it to the blockchain smart contract.
6. The data auditing method based on blockchain oracle for supporting secure deduplication according to claim 1, characterized in that, The blockchain smart contract audits the stored data according to the challenge response, including: The blockchain smart contract executes a preset algorithm to audit and verify the challenge response. If the audit verification passes, return the margin to the cloud service provider and determine whether the data needs to be stored on the cloud service provider continuously. If the audit verification fails, punish the cloud service provider by deducting the margin, and use the deducted margin as compensation and send it to the data owner.
7. The data auditing method based on a blockchain oracle for supporting secure deduplication according to claim 1, wherein Before the oracle encrypts the data to be stored by the data owner, the oracle performs BCH coding on the data to be stored by the data owner, so that there is a corresponding relationship between the codes of each codeword, so as to perform data integrity verification according to the inter-code relationship when the data owner accesses the data.
8. The data auditing method for supporting secure deduplication based on a blockchain oracle according to claim 7, characterized in that, Perform data integrity verification according to the inter-code relationship, including: For the data access requirements of the data owner, use the blockchain smart contract to call the oracle, download the corresponding data ciphertext from the cloud service provider through the oracle and generate a hash value corresponding to the data ciphertext using a hash function, and use the hash value as the data integrity identifier. Obtain the key corresponding to the data owner's identity ID and the data duplicate check hash value from the cross-chain, and decrypt the data ciphertext using the key to obtain the plaintext data. Compare the data integrity identifier with the data duplicate check hash value. If the two are equal, the data ciphertext integrity verification passes. If they are different, the data ciphertext integrity verification fails. Use the decrypted plaintext data as the recombined data, correct the errors of the recombined data using the BCH code to obtain the error-corrected data, divide the error-corrected data into several message blocks, and generate an encryption key for each message block using a hash function. Compare it with the key obtained from the blockchain. If they are equal, the error correction is successful, and the error-corrected data is stored in the new cloud service provider again. If they are not equal, the error correction fails.
9. A data audit system based on a blockchain oracle that supports secure deduplication, characterized in that, Include: an encryption module, a storage module, and an audit module, where The encryption module is used to, for the data to be stored by the data owner, use the blockchain smart contract to call the oracle, encrypt and deduplicate the data to be stored by the data owner through the oracle, upload the deduplicated encrypted data to the cloud service provider, and upload the encryption parameters to the blockchain for storage. The encryption parameters at least include the data owner's identity ID, key, and data duplicate check hash value. The storage module is used for the cloud service provider to sign an intelligent contract for auditing response incentive rewards and punishments with the oracle and pay the corresponding margin, and store the uploaded encrypted data. An auditing module, which is used for the oracle to regularly send data auditing challenges to the cloud service provider, so as to utilize the cloud service provider to make corresponding challenge responses to the data auditing challenges, and the blockchain smart contract audits the stored data according to the challenge responses.
10. An electronic device, characterized in that, It includes: At least one processor and a memory coupled to the at least one processor; Wherein, the memory stores a computer program, and the computer program can be executed by the at least one processor to implement the method according to any one of claims 1 to 8.